@mjg59@nondeterministic.computer
Post #3933876
2026-07-19 11:59 UTC
Microsoft has been a reasonable steward of the third party UEFI signing key and handling revocation, but I think it's reasonable to question the conflict of interest around the Windows signing key and the huge amount of time between Windows bootloader vulnerabilities being identified and Microsoft revoking them. Ideally this would be delegated to a third party, but an alternative would be for Microsoft to issue a signed (but optional) dbx update that revoked trust in the Windows signing key
Replies (3)
-
@wdormann@infosec.exchange 2026-07-19 12:35
@mjg59@nondeterministic.computer Baton Drop CVE-2022-21894 came out what, 4.5 years ago? Manual user interaction is still required to apply a protection against it.
-
@mjg59@nondeterministic.computer 2026-07-19 12:00
People outside the Windows ecosystem could apply this and not worry about vulnerabilities in the Windows ecosystem, without Windows users having to worry about their recovery images becoming unbootable
-
@crlf@infosec.exchange 2026-07-21 00:08
@mjg59@nondeterministic.computer if I remember correctly, you can install your own "UEFI CA", and replace the default ones. Of course, that has the drawback that you then need to handle your own "UEFI CA"...